Endpoint Protection

 View Only
  • 1.  Action taken on risk: Left alone

    Posted May 28, 2014 05:45 AM

    Recently when scheduled scans detect a risk the action taken is "left alone" can anyone advise why this might be happening.

    Below is an example:

    At least one security risk found:

    Risk name: Infostealer.Limitail
    File path: C:\Users\
    Blanked out\TT PAYMENT COPY. (1) TT.rar>>attachment2.exe
    Event time: 28/05/2014 8:55:54 PM
    Database insert time: 28/05/2014 8:56:55 PM
    Source: Scheduled Scan
    Description: ""
    User: SYSTEM
    Computer:
    Blanked out
    IP Address: Blanked out
    Domain:
    Blanked out
    Server: Blanked out
    Client Group: My Company\Blanked out\Desktop & Laptops\Central\
    Action taken on risk: Left alone
    This alarm was generated at 28/05/2014 9:03:14 PM (Reporter host Time).
    This alarm was generated by admin, with the following filters:

    =======================================================================================

    I've checked out scan settings and actions which are:

    First Action: Clean Risk

    If first action fails: Delete Risk

    Yet detections are left alone??

     

    However if I do a manual scan it quarinties the files as expected.

    Filename Risk Action Risk Type
    attachment2.exe Infostealer.Limitail Quarantined Compressed file; Virus
    TT PAYMENT COPY. (1) TT.rar Infostealer.Limitail Quarantined Compressed file; Virus

    Any ideas.



  • 2.  RE: Action taken on risk: Left alone

    Posted May 28, 2014 05:52 AM

    Best Practices for responding to "Left Alone" in the virus or threat history log

    Article:TECH101661 | Created: 2006-01-13 | Updated: 2013-11-05 | Article URL http://www.symantec.com/docs/TECH101661

    You can scan Threat Analysis

    How to run the Threat Analysis Scan in Symantec Help (SymHelp)

    Article:TECH215519 | Created: 2014-03-03 | Updated: 2014-03-07 | Article URL http://www.symantec.com/docs/TECH215519

    See this thread

    http://www.symantec.com/connect/forums/sep-logs-actual-action-left-alone



  • 3.  RE: Action taken on risk: Left alone

    Posted May 28, 2014 06:18 AM

    Many reasons:

    http://www.symantec.com/docs/TECH101661

    Reboot the machine into safemode and remove that way